ISC2 Certified in Cybersecurity (CC)Security OperationsMedium

A company is implementing a new policy for handling sensitive customer data. The policy states that all employees who interact with this data must undergo specific training modules annually and sign an acknowledgment of their responsibilities. Which aspect of security operations does this primarily address?

  1. AThird-party risk management
  2. BPersonnel security
  3. CData handling
  4. DSecurity awareness training
Show answer & explanation

Correct answer: B. Personnel security

Personnel security focuses on the human element of security, including policies, procedures, and training related to employees, contractors, and third parties who have access to an organization's assets. Requiring training and acknowledgments for data interaction falls directly under managing personnel risks.

Why the other options are wrong

  • A. Third-party risk management focuses on external vendors, not the organization's own employees.
  • C. Data handling defines how data is processed, but personnel security ensures *people* handle it correctly.
  • D. Security awareness training is a *component* of personnel security, but personnel security is the broader practice covering all aspects of managing human risk.

Personnel Security

The practice of managing human-related security risks through policies, procedures, and controls for employees, contractors, and other individuals.

  • Covers hiring, onboarding, ongoing training, and termination.
  • Aims to prevent insider threats and human error.
  • Includes background checks, awareness training, and access control.

Memory trick: People are the weakest link, so personnel security strengthens them.

More Security Operations questions